πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,407
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 30, 2026
Last Updated

40,407 vulnerabilities found (page 1317 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
630e5edb-8f09-49cc-b396-451b035285bc MEDIUM 4.4 The PE Easy Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
6309c706-f84a-4997-9a9b-1bd8cf8f711a
< 2.8
MEDIUM 4.4 The Knowledge Center plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up… wordfence
62d847f7-bd07-48c6-a083-06d7255ed7e2
< 3.2.1
MEDIUM 4.4 The Sessions plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.0 d… wordfence
62c9ff4d-e098-4b71-ac0e-7e1d22637560 MEDIUM 4.4 The Delay Redirects plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
6294acc4-e28a-4817-be3e-430086c05e13
< 5.7.50
MEDIUM 4.4 The Icegram Express formerly known as Email Subscribers – The Ultimate Email Marketing & Automation Plugin for WordPre… wordfence
628c44f1-2458-4b43-bcb1-8e077c32bdbc MEDIUM 4.4 The Flag Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2 d… wordfence
6288fddf-926f-4506-94de-696e0a23766d
< 6.4.7
MEDIUM 4.4 The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … wordfence
62623042-8d31-44df-b31a-874a9aa9dcb3
< 1.3.17
MEDIUM 4.4 The WP Weixin theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.16 … wordfence
62233370-3b54-4d89-93e7-07afdae4a413
< 12.8
MEDIUM 4.4 The WP Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version… wordfence
61fe8efe-b51c-4cf4-8a5e-12fa2c0b48df MEDIUM 4.4 The WP Voting Contest Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
61ec0772-8b3a-41de-b484-f0cd56db47c6
< 4.1.24
MEDIUM 4.4 The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al… wordfence
61c815c2-a5ea-431c-bfde-c08a4eb5fda6
< 5.3
MEDIUM 4.4 The Schedule Posts Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in vers… wordfence
61a04c77-28ef-4a3f-8e6c-95a98fcc994d MEDIUM 4.4 The Duplicate Page and Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
61771b13-4554-49b8-8829-6345174c4a69
< 6.0.5
MEDIUM 4.4 The WappPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, an… wordfence
613b4ad3-9aea-4c1c-9d73-1fb51da26477
< 3.6.0
MEDIUM 4.4 The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versio… wordfence
611a2adc-2b0b-460e-b988-d9bcb3f92807
< 1.2.0
MEDIUM 4.4 The Document Library Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
61068993-46e2-4ac6-96a4-52c6dcc56b0d
< 2.5.3
MEDIUM 4.4 The CYAN Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up … wordfence
60e6b9e0-6e2f-4a2d-b967-cc410ebd3d7d
< 3.8.7
MEDIUM 4.4 The WP QuickLaTeX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Background Color field in al… wordfence
60a8b4b4-a54a-41d2-adff-5bf9d1934b96 MEDIUM 4.4 The Social Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2… wordfence
607f07d8-033f-467c-90bf-834ea2753eaf MEDIUM 4.4 The Geocache Stat Bar Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all… wordfence
603813a4-73e1-47fd-8a6c-9416d21b6c88
< 3.33.0
MEDIUM 4.4 The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in al… wordfence
5fe46da6-add5-42d4-a2db-7a8bada2968c MEDIUM 4.4 The WP Post Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… wordfence
5f977890-4bd7-4a12-822d-33e364677c6d MEDIUM 4.4 The Sales Count Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
5f88cafb-58aa-4a04-9988-7e51f6feccfc MEDIUM 4.4 The WP Airdrop Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
5f0d1434-d29c-434c-97f9-ef949d23e680 MEDIUM 4.4 The Owl Carousel WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
← Prev 1314 1315 1316 1317 1318 1319 1320 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top